Previous Topic: Risk Score and AdviceNext Topic: User Device Association


Risk Evaluation Rules

The Advanced Authentication service provides the following risk evaluation rules:

Consider an example scenario where four rules are configured in the following order:

  1. Negative IP, with a score of 85
  2. User Velocity, with a score of 70
  3. Device Velocity, with a score of 65
  4. DeviceID Known, with a score of 30

If the Advanced Authentication service determines that a transaction is coming from a negative IP address, then it returns a score of 85 (DENY), based on the first configured rule that matched. Another transaction exceeding the configured Device Velocity gets a score of 65, which results in a request for increased authentication.